PT-2012-5454 · Openfabrics Alliance+2 · Librdmacm+2

·

CVE-2012-4516

·

Publicado

2012-10-22

·

Atualizado

2023-02-13

CVSS v2.0

5.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions librdmacm version 1.0.16
Description The issue allows remote attackers to specify address resolution information for the application via a malicious ib acm service when ibacm.port is not specified, causing librdmacm to connect to port 6125.
Recommendations For librdmacm version 1.0.16, consider specifying the ibacm.port to avoid connecting to the default port 6125, which can be exploited by a malicious ib acm service. As a temporary workaround, restrict access to the ib acm service to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CESA-2013_1661
CVE-2012-4516
RHSA-2013:1661
RHSA-2013_1661

Produtos afetados

Centos
Red Hat
Librdmacm